Vulnerability PYSEC-2026-180
Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 months ago
May 27, 2026 at 05:16 PM UTC
No summary available
0.0.1 - 8.3.0
0.0.1 - 8.3.0
Details
Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote .m3u8 HLS playlist or .mpd DASH manifest can list file:///path/to/file as a segment, and streamlink will read that local file and write its contents to the output stream. This vulnerability is fixed in 8.4.0.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 days ago
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files
0.0.1 - 8.5.0 GHSA-vf2x-4v53-pm7v
0.0.1 - 8.5.0 GHSA-vf2x-4v53-pm7v
Medium Risk
4 months ago
Streamlink has an arbitrary local file read via file:// URI in HLS and DASH
0.0.1 - 8.3.0 GHSA-hgqw-6m45-hw5f
0.0.1 - 8.3.0 GHSA-hgqw-6m45-hw5f
Impacted packages
Timeline
Published
4 months ago
May 27, 2026 at 05:16 PM UTC
Fixed (8.4.0)
4 months ago
May 06, 2026 at 06:15 PM UTC
Last Modified
3 months ago
June 02, 2026 at 12:15 PM UTC